惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
P
Privacy International News Feed
Vercel News
Vercel News
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
博客园 - 叶小钗
F
Fortinet All Blogs
Security Archives - TechRepublic
Security Archives - TechRepublic
L
LINUX DO - 最新话题
AWS News Blog
AWS News Blog
Engineering at Meta
Engineering at Meta
Attack and Defense Labs
Attack and Defense Labs
Recent Announcements
Recent Announcements
Recent Commits to openclaw:main
Recent Commits to openclaw:main
PCI Perspectives
PCI Perspectives
Cloudbric
Cloudbric
AI
AI
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
IT之家
IT之家
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
J
Java Code Geeks
M
MIT News - Artificial intelligence
Cisco Talos Blog
Cisco Talos Blog
V2EX - 技术
V2EX - 技术
Webroot Blog
Webroot Blog
Microsoft Security Blog
Microsoft Security Blog
Cyberwarzone
Cyberwarzone
博客园 - 聂微东
G
Google Developers Blog
W
WeLiveSecurity
罗磊的独立博客
P
Privacy & Cybersecurity Law Blog
阮一峰的网络日志
阮一峰的网络日志
A
About on SuperTechFans
WordPress大学
WordPress大学
The GitHub Blog
The GitHub Blog
T
Tailwind CSS Blog
V
Visual Studio Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
S
Secure Thoughts
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
Google DeepMind News
Google DeepMind News
Google DeepMind News
Google DeepMind News
雷峰网
雷峰网
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
F
Full Disclosure
Blog — PlanetScale
Blog — PlanetScale
The Last Watchdog
The Last Watchdog
P
Proofpoint News Feed

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
ISP proxies, AI crawlers, and the slow death of datacenter IPs: 2026 in numbers
Romeo Mihalc · 2026-05-05 · via DEV Community

TL;DR

Bots passed humans on the open web. IP reputation feeds stopped working for residential traffic. IPv4 prices collapsed. AI crawlers became a measurable tax on public sites. And Europe finally started writing big GDPR checks while only fining 1.3% of complaints. If you ship anything that touches the public web at scale, the IP infrastructure you set up in 2022 is doing more harm than good in 2026.

The headline numbers:

  • 51% of all web traffic in 2024 was automated. Bots beat humans for the first time in a decade. (Imperva 2025 Bad Bot Report)
  • 37% was bad bots specifically, up from 32% in 2023. Sixth straight yearly increase.
  • 2.8% of websites tested in 2025 were fully protected against bots, down from 8.4% the year before. (DataDome 2025 Global Bot Security Report)
  • 78% of residential-IP sessions in a 4-billion-session study evaded conventional IP reputation feeds. (GreyNoise / IPInfo, April 2026)
  • <$21/IP for large-block IPv4 transfers in May 2025. Roughly a 10-year low. (IPv4.Global)
  • +187% YoY growth in AI-driven traffic in 2025. (HUMAN Security)
  • 62% → 90% of investment firms using alternative data, in two years. (Lowenstein Sandler)
  • €1.15B in GDPR fines from EU DPAs in 2025; only 1.3% of complaints actually result in a fine. (EDPB; noyb)

Bots overtook humans in 2024 and the gap keeps widening

If you've shipped a scraper in the last two years you already feel this. The data behind the gut feeling: 51% of web traffic in 2024 was automated, per Imperva. Bad bots specifically were 37%, up from 32%. That 5-point jump is the largest single-year increase in Imperva's twelve-year time series.

The defense side moved the wrong way. DataDome tested over 16,900 sites across 22 industries in 2025 and found only 2.8% were fully protected, down from 8.4% in 2024. 61% of domains failed to detect a single test bot.

That's not a story about bot mitigation getting worse. It's a story about generative AI lowering the cost of writing request-level automation. People who couldn't afford a developer can now prompt one.

The target surface shifted too. 44% of advanced bot traffic now hits APIs instead of HTML pages. Verizon's 2025 DBIR puts the median rate of credential-stuffing activity across SSO providers at 19% of daily auth attempts. Roughly one in five logins at identity-provider scale is machine-driven. That's wild.

Why datacenter IPs stopped working

A joint GreyNoise / IPInfo study published in April 2026 examined 4 billion edge-attack sessions over three months. The findings:

  • 39% of those sessions came from residential IPs.
  • 78% of the residential-IP sessions evaded IP reputation feeds entirely.
  • 89.7% of the malicious residential IPs were active for under a month before rotating out.

Static IP blocklists, the backbone of anti-bot defense for a decade, no longer carry the signal they used to.

Detection now has to come from somewhere else: behavior over time, browser fingerprint, session history, telemetry. The IP alone tells defenders very little.

That sets up a weird market. Residential-class IPs are the dominant workaround, and the underlying economics got cheap fast.

IPv4 prices collapsed

Large-block (/16+) transfer prices fell to under $21 per IP in May 2025, the lowest in roughly a decade per IPv4.Global. 8,062 IPv4 transfers were recorded globally in 2025, near an all-time high in transfer volume. Monthly lease rates sit at roughly $0.40 to $0.50 per IP.

The structural reason: IPv6 finally caught up. Google reports US IPv6 share crossed 50% in February 2025; France hit ~86% by February 2026. New enterprise workloads are migrating to v6, and incumbents are liquidating hoarded v4 blocks. An ISP proxy is, structurally, an IPv4 lease on a reputable consumer-ISP ASN with the right reverse DNS pointer. Those numbers set the floor on unit economics across the sector.

The AI crawler problem nobody had two years ago

This one sneaks up on you if you run any public site with content.

Cloudflare measured AI crawlers at ~8.7% of all HTML request traffic in 2025. Googlebot was 4.5%; the other AI bots together were ~4.2%. User-driven AI crawls (someone hits "research this" in their assistant) grew 15× year over year.

HUMAN Security's 2026 State of AI Traffic benchmark reports AI-driven traffic up 187% YoY, with agentic-browser traffic up 7,851%. Akamai counted 25 billion AI-bot requests to commerce sites in July and August 2025 alone. DoubleVerify attributes 86% of the General Invalid Traffic increase in 2025 to AI crawlers, not classical fraud.

If you're an SRE, AI crawlers are now a meaningful share of your tail-latency budget, and they aren't all polite about robots.txt. If you're building anything that needs a clean read of the live web at scale (alt data, market intel, training corpora) you're competing for IP infrastructure with everyone running an LLM.

Comparison: datacenter vs rotating residential vs ISP proxies

If you're picking infra in 2026, here's the practical shape of the tradeoff:

Dimension Datacenter Rotating residential ISP (static residential)
ASN type Hosting (AWS, Hetzner, GCP) Consumer ISPs via real devices Consumer ISPs, hosted on servers
IP reputation pass rate Low. Detected within hours on protected sites. High. ~78% evade reputation feeds. High. Same ASN trust as residential.
Session stability High Low. IP rotates on device reconnect. High. Static IPs, server-grade uptime.
Speed Fast (~ms) Variable, often slow Fast (~ms)
Best fit Internal tools, low-protection targets Throwaway high-volume scrapes Long sessions, logged-in flows, ad verification, SERP
Worst fit Anything with modern bot detection Cart fills, auth flows, multi-step scrapes Pure rotation needs

The middle column is where rotating residential pools shine. The right column is where ISP proxies pay for themselves: anything that needs the same IP across a 20-minute logged-in session, or geo-stable for a SERP scrape, or trusted enough to render real ads instead of cloaked decoys.

What teams are actually buying this stuff for

Five workloads dominate the buyer mix in 2026, and the numbers behind each are big enough to matter:

  1. Retail price monitoring. Global e-commerce hit $6.42T in 2025, 20.5% of all retail (eMarketer). McKinsey's classic finding still holds: a 1% price improvement yields about 8.7% operating-profit lift. At that elasticity a continuous competitor scan pays for itself in weeks. Datacenter scrapes against major retailers now get silently poisoned with bad prices instead of blocked, which is worse than blocked.
  2. Ad verification. US digital ad revenue hit $294.6B in 2025 (IAB/PwC). Programmatic was $162.4B of it. The ANA reports $26.8B of programmatic spend leaked to inefficiency in Q2 2025 alone, up 34% in two years. You need real residential IPs in the right geos to see what campaigns actually look like for end users.
  3. Travel fare aggregation. Imperva found 48% of travel-industry traffic in 2024 was bad bots, the highest share of any sector. Skift reports the top four OTAs control 96% of the sector's $58B in revenue. Metasearch teams need stable residential egress just to keep rates fresh.
  4. SEO / SERP rank tracking. SEO software is an $84.9B market in 2025 (Fortune Business Insights), forecast to $154.6B by 2030. Personalized SERPs make rank tracking from scraping farms unreliable; agencies need geo-distributed residential egress.
  5. Alternative data for hedge funds. This one's the sleeper hit. Investment firms using alt data jumped from 62% in 2023 to 90% in 2025 (Lowenstein Sandler). 89% plan to grow budgets. Two-thirds already spend $1M+ per year. Grand View projects the alt-data market at $135.7B by 2030 from $11.65B in 2024, a 63.4% CAGR.

If you've wondered who writes the checks for residential IPs at industrial scale, it isn't marketing teams. It's quants and LLM labs.

The legal track moved more than most teams realize

Two years of case law and regulation worth knowing before you ship a commercial scraper:

US: scraping public data is defensible. Van Buren v. United States (2021) read the CFAA's "without authorization" language narrowly. The Ninth Circuit reaffirmed hiQ Labs v. LinkedIn in 2022; that case eventually settled for $500K plus a permanent injunction and data destruction. Public-data scraping at the appellate level is, post-hiQ, on solid ground.

EU: enforcement scaled, but base rate stays low. National DPAs issued €1,145,760,374 in GDPR fines during 2025 (EDPB). Cumulative fines since 2018 sit above €4.2B across 6,680+ decisions. The counter-signal worth pinning to your wall: only 1.3% of complaints brought to EU DPAs end in a fine, per noyb. Headline totals are real. The base rate per complaint is much lower than the totals imply.

EU Data Act and AI Act. The Data Act applies from 12 September 2025. The AI Act's Article 53 requires general-purpose AI providers to respect Article 4(3) machine-readable opt-outs and publish a "sufficiently detailed summary" of training data, including main scraped domains. Territorial scope follows EU market placement, so EU training-data compliance effectively exports anywhere a model is sold in Europe.

California woke up. The California Privacy Protection Agency's largest fine to date is $1.35M against Tractor Supply in September 2025, on Global Privacy Control non-compliance. The CPPA has telegraphed that GPC compliance is the priority enforcement vector through 2026.

None of this is legal advice. Talk to a lawyer before scaling anything commercial.

FAQ

What's an ISP proxy in plain terms?
A server-hosted IP address that originates from a consumer ISP's ASN (Comcast, Verizon, BT, Deutsche Telekom, etc.) instead of a datacenter ASN (AWS, Hetzner, GCP). Sometimes called a static residential proxy. From a target site's perspective it looks like home broadband, but it runs on server hardware for speed and session stability.

Why not just use rotating residential IPs?
For workflows that need a stable session (logged-in scrapes, multi-step flows, cart fills, ad verification) IP rotation breaks things. ISP proxies give you residential-grade trust without the volatility.

Are datacenter proxies actually dead?
For modern bot-protected targets, in practice yes. They still work for low-protection internal tools, certain APIs, or staging. They will not survive a price-monitoring run against a Tier-1 retailer or a SERP scrape on a tracked term.

How much do ISP proxies cost in 2026?
Underlying IPv4 lease rates are about $0.40 to $0.50 per IP per month, after large-block transfer prices fell under $21 per IP in 2025. Retail pricing has tracked those costs down. Single-digit dollars per IP per month is the realistic range at scale.

Is scraping legal?
Public-data scraping in the US is defensible after Van Buren and the Ninth Circuit's reaffirmation of hiQ. EU collection requires GDPR, EU Data Act (effective 12 Sept 2025), and AI Act compliance for any training-data use. Talk to a lawyer before scaling anything commercial.

How big is the proxy market really?
Mordor Intelligence sizes the residential proxy server software market at $122M in 2025, growing to $148M by 2030 (3.98% CAGR). The downstream markets that consume the IP layer are where the growth is: web scraping at $1.03B → $2.23B by 2031, alternative data at $11.65B → $135.7B by 2030.

What changed in the last 12 months specifically?
Three things. AI crawler traffic became a measurable, named tax on the public web. IPv4 prices collapsed alongside IPv6 finally crossing 50% in major markets. And IP reputation feeds, the load-bearing component of bot defense for a decade, are now functionally defeated for residential traffic.

What I'd tell someone starting fresh in 2026

If you're building automation that touches the public web at scale, your IP layer is no longer set-it-and-forget-it. Datacenter IPs are first-resort blocked, rotating residential pools break logged-in flows, and the IPs that work for serious work are residential-grade with stable sessions. That's the gap ISP proxies fill, and the data behind that gap is the rest of this post.

A few honest closing notes. The Mordor residential-proxy figure ($122M) is software-revenue scope only; broader sizings that bundle bandwidth resale and DaaS spend run an order of magnitude larger. The 51% bot share number from Imperva is measured against sites under their protection (so skewed toward enterprise targets attackers hunt). Cloudflare's ~30% bot share over the full anycast network is not the same denominator. Both numbers are correct at their stated scope. Don't conflate them.

This post was written by the team behind anonymous-proxies.net. We sell ISP proxies among other products. The full long-form analysis with all 50+ data points, every primary-source citation, the mega-table, and the methodology notes lives here:

https://anonymous-proxies.net/posts/isp-proxies-statistics-2026/